People confide things in these apps that they haven't told a soul. That's the product working as designed, and it's the reason to spend ten minutes looking at how your words are handled before you send the first message, not after a news story breaks.
First, a reality check on encryption
End-to-end encryption can't exist in this setup. To reply to you, the app's servers have to read what you typed. An app that advertises end-to-end encryption for chats is either dressing up ordinary transport encryption or talking about something other than the conversation.
That isn't a scandal, just how the technology works. It means the questions that matter are about how long data is kept and who gets to see it, not about cryptography.
Check 1: what else is collected besides the chat
Your messages are the obvious part. The less obvious parts include:
- Your account details, and whether you can sign up with a spare email rather than your main one.
- Payment records. In this category they're the most revealing trail you leave, and a descriptor on a card statement has outed more people than any breach has.
- Device and usage data, such as when you open the app and how long you stay.
- Generated images, which sit on the company's servers whether you saved them or not.
Check 2: does it train a model?
Search the privacy policy for phrases like "improve our services" or "train". Then see whether the settings offer an opt-out.
In practice you'll find one of three setups: no training on your content, training with an opt-out, or training with no control you can see. Any of them can be livable. Not knowing which one you're in is the real problem.
Check 3: how long it's kept, and what deleting does
Policies tend to blur two separate things. Retention is how long your content stays while the account is live. Deletion is what happens once you ask for it to go. An app might wipe your conversations on request but hang on to generated images, billing records and backups for longer. That can all be perfectly lawful and still not be what you expected.
The details are in deleting an AI companion account.
Check 4: what rights you have in New Zealand
The Privacy Act 2020 and its Information Privacy Principles let you ask any organisation for the personal information it holds about you (Principle 6). It must respond within 20 working days, and can extend that only with reasons and notice of your right to complain. If it won't help, you complain to the company's privacy officer first, then to the Office of the Privacy Commissioner (0800 803 909), which can investigate, settle a complaint and issue access directions. Chasing a small overseas operator is harder than chasing a local one, so check whether it gives you a way to make the request at all.
New Zealand law doesn't hand you a blanket GDPR-style right to erasure either, but you can still ask, and the privacy principles limit how long a business may keep information it no longer needs. Our Dutch and French editions cover the same apps under GDPR, which is stricter in this area.
The better test isn't whether the rights exist, because they do. It's whether the app has a self-serve button or expects you to email an address and wait. That tells you a lot about how the company sees its users.
A five-minute setup that costs nothing
Set up a separate email address. Look at what shows on your card statement before month two. Turn training off if there's a switch. And decide now what you won't type into a service that has to store it: your employer's name, your home address, anything about a third person who never agreed to be in your chat log.
Replika and Nomi are the two apps in our ranking most likely to pile up years of this material rather than weeks, because they're built around long-term continuity. That makes the five minutes even more worthwhile there.

